VeriScan™ by Quantyva™
Services How It Works Pricing Contact
Submit for Review
Legal

Privacy Policy

How we collect, use, and protect your personal data in compliance with the EU General Data Protection Regulation (GDPR).

Last updated: 28 May 2026 Effective: 28 May 2026 Controller: Quantyva™
Contents
1. Data Controller 2. Data We Collect 3. How We Use Your Data 4. Legal Basis 5. Retention Periods 6. Sharing & Processors 7. International Transfers 8. Your Rights 9. Security 10. Cookies 11. Changes 12. Contact Us

Summary: VeriScan is operated by Quantyva™ (BrandX Invest). We collect only the information needed to deliver your packaging compliance audit. We never sell your data. All files are treated as confidential. You have full GDPR rights at any time.

1. Data Controller

The data controller responsible for your personal information is:

Quantyva™ (operated under BrandX Invest)
EU Company Registration: ROONRC.J2024000390307
Service brand: VeriScan™
Website: veriscanaudit.com
Contact: privacy@veriscanaudit.com

References to "VeriScan", "Quantyva", "we", "us", or "our" in this Policy all refer to the entity above.

2. Data We Collect

We collect personal data only when you actively provide it to us — through our intake form, email, or direct contact. We do not track you across the web.

2.1 Data you provide directly

CategoryExamplesWhy collected
IdentityFull name, job titleTo address reports correctly and verify client relationship
ContactBusiness email address, company nameTo deliver reports and communicate about your order
Business informationCountry of brand registration, target marketsTo scope the correct audit and applicable regulations
Packaging filesPDF, AI, PNG or JPEG artwork uploadsCore subject of the compliance audit service
Order detailsService type selected, add-on modulesTo process and deliver the correct audit report
NotesFree-text context or regulatory questionsTo tailor the audit to your specific concerns

2.2 Data collected automatically

When you visit veriscanaudit.com, our hosting provider may automatically log basic technical data: IP address, browser type, pages visited, and timestamps. This data is used solely for security and performance monitoring. We do not use this data for advertising or profiling.

3. How We Use Your Data

We use your data for the following purposes only:

  • Service delivery: To analyse your packaging against applicable EU and country-specific regulations and produce your compliance report.
  • Communication: To respond to your enquiry, confirm receipt of files, clarify scope, and deliver your report.
  • Billing and invoicing: To issue quotes and invoices for services rendered.
  • Legal compliance: To meet our obligations under EU law, including retaining business records for statutory periods.
  • Service improvement: Aggregate, anonymised analysis of common compliance issues to improve our audit methodology. Individual client data is never used for this purpose without explicit consent.

We do not use your data for: direct marketing without consent, automated profiling, or any form of resale or data brokering.

4. Legal Basis for Processing

Under GDPR Article 6, we rely on the following legal bases:

  • Contract performance (Art. 6(1)(b)): Processing your contact details and packaging files is necessary to deliver the audit service you have requested.
  • Legitimate interests (Art. 6(1)(f)): Technical logs for security monitoring and fraud prevention, where our interests do not override your fundamental rights.
  • Legal obligation (Art. 6(1)(c)): Retention of invoices and business records as required by Romanian commercial and tax law.
  • Consent (Art. 6(1)(a)): For any optional marketing communications (newsletter, product updates). You may withdraw consent at any time.

5. Retention Periods

Data typeRetention periodReason
Packaging artwork files30 days after report deliverySupport period for follow-up questions; then permanently deleted
Compliance report (copy)12 monthsTo handle disputes or re-issue requests
Contact details and order records3 yearsLegitimate business interest; client relationship management
Invoices and financial records7 yearsRomanian legal requirement (Legea contabilității nr. 82/1991)
Email correspondence3 yearsDispute resolution and audit trail
Technical server logs90 daysSecurity monitoring

After the applicable retention period, data is securely deleted or anonymised.

6. Sharing & Third-Party Processors

We do not sell, rent, or trade your personal data. We share data only with trusted processors strictly necessary to operate the service:

  • Formspree (formspree.io): Processes form submissions sent through our intake form. Data is transmitted securely and used solely for message delivery.
  • Cloud storage provider: Packaging files uploaded by clients are stored in encrypted cloud storage accessible only to our compliance team.
  • AI processing tools: Packaging text content may be processed by AI tools to assist analysis. Providers are selected under GDPR-compliant data processing agreements and are not permitted to train on client data.
  • Accounting software: Invoice data (name, company, amount) is processed in our accounting system for statutory bookkeeping.

All processors are bound by contractual data processing agreements (DPAs) under GDPR Art. 28. We do not share your data with any third party for their own marketing or commercial purposes.

We may disclose data to legal authorities if required by law, court order, or to protect the legal rights of Quantyva™.

7. International Data Transfers

Quantyva™ is registered in Romania, an EU member state. Your data is processed within the European Economic Area (EEA) wherever possible.

Where any processor is located outside the EEA (for example, certain cloud services), we ensure that appropriate safeguards are in place — including Standard Contractual Clauses (SCCs) approved by the European Commission — before any transfer takes place.

8. Your Rights Under GDPR

As a data subject, you have the following rights. You may exercise any of these at any time by contacting us at privacy@veriscanaudit.com:

  • Right of access (Art. 15): Request a copy of all personal data we hold about you.
  • Right to rectification (Art. 16): Ask us to correct inaccurate or incomplete data.
  • Right to erasure (Art. 17): Ask us to delete your personal data where there is no legitimate legal reason to continue processing it.
  • Right to restrict processing (Art. 18): Ask us to pause processing of your data while a dispute is resolved.
  • Right to data portability (Art. 20): Receive your personal data in a structured, machine-readable format.
  • Right to object (Art. 21): Object to processing based on legitimate interests, including profiling.
  • Rights related to automated decision-making (Art. 22): We do not make automated decisions with legal or significant effects on you.

We will respond to all requests within 30 days. If we cannot fulfil a request (for example, due to a conflicting legal obligation), we will explain why.

You also have the right to lodge a complaint with your national data protection authority. In Romania, this is the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) at dataprotection.ro. If you are located in another EU country, you may contact your local DPA.

9. Security Measures

We take the security of your data seriously and apply appropriate technical and organisational measures, including:

  • HTTPS/TLS encryption for all data in transit
  • Encrypted storage for uploaded packaging files
  • Access controls: packaging files accessible only to the compliance team member assigned to your report
  • No sharing of client files by email without password protection or secure transfer links
  • Automatic deletion of files at the end of the applicable retention period
  • Regular review of third-party processor security standards

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and, where required, notify you directly without undue delay.

10. Cookies

Our website uses only essential cookies necessary for basic site functionality (session management, form security). We do not use advertising cookies, tracking pixels, or third-party analytics that identify you personally.

You can configure your browser to block all cookies; however, this may affect the functionality of our intake form.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we make material changes, we will update the "Last updated" date at the top of this page. If you have an active client relationship with us, we will notify you by email.

We encourage you to review this Policy periodically.

12. Contact Us

For any questions, requests, or concerns relating to this Privacy Policy or your personal data, please contact us:

Quantyva™ — Privacy & Data Protection
Email: privacy@veriscanaudit.com
Subject line: "GDPR Request — [your name]"

We aim to acknowledge all requests within 5 business days and to resolve them within 30 days as required by law.

VeriScan™ by Quantyva™

Premium packaging compliance review for food brands entering Italian, Spanish, and French markets.

Services

Essentials Audit Multilingual Audit Pro & Full EU Audit

Company

How It Works Submit for Review

Legal

Privacy Policy Terms of Service NDA & Data Handling
© 2026 Quantyva™ (BrandX Invest) — ROONRC.J2024000390307. All rights reserved.
Privacy Policy Terms of Service Contact